Hacked again

Stephen,

We’re hacked again. This time, they replaced all site’s index.html with a hacked-style index, as you can see here:

URL REMOVED

We already restored all of ours index.html and even removed, just in case, a WP 2.1.2 (on theory clean), but actually we are really on panic here.

Please, we need to know ASAP from where (script/page) this hacker is breaking in.

Thanks in advance, Ignacio Marcos.

You have quite a large number of domains and logs for every one will have to be analyzed, it will take a long time to get back to you with a number of hours of work

Stephen,

Don’t waste your time. I already spoke with the hacker, and already know from where they did it.

Wich we really need now is a site backup restore, please:

helenaestrada.com
(from january 07 please).

Thanks, Ignacio Marcos.

You actually spoke with the hacker??? I would love to hear how you tracked him/her down and how that conversation went.

Care to share?

Not at all, the “hacker”, a 15 years old boy, defeated some of my domains, putting an index.html with something like this:

“Hacked by “The biggest hacker”, bla, bla, bla.. contact me at www.thebiggesthacker.com

LOL

Ironically, he has a forum on his website where I could post about his action, and later contact him through mail. Even when I found an initial “pardon-attitude” from him, he ask me to trade the bug for a link in one of my sites! incredible! finally I found some personal information (full name, phone, address) of this “hacker” on some of his whois domain information, and then he decided to give me the answer: an inactive shoutbox wich allows (not anymore :wink: ), file uploads (even PHPs!).

Regards, Ignacio.

Just came across a site of mine that was hacked around this time. It’s my service domain, only used to provide the hsphere server aliases, and the site consisted of nothing more than a basic homepage directing people to my .com site, which is why it hasn’t been spotted by me since then.

No website lost, but this is a site potential clients may well have looked at to see if my company was a reputable one; where the nameservers belong etc. (mycompany.net rather than mycompany.com)

Now it seems that JH knew the server had been hacked and lots of websites had had their index pages replaced. So, why wasn’t I notified so I could check mine? I have no idea if I lost any potential clients in the meantime. I’d rather spend half-an-hour checking my and my clients homepages than find out two months after the event that my site has been advertising some pathetic teenager all this time instead of reflecting a professional image.

(and I have checked the contact details were correct)

bro,

There were not that many files replaced, I am sorry it happened, win5 is being upgraded very shortly and the bug used has actually already been corrected but windows 2003 will prevent it even more, but we saved backups over two months, for those that we did not see had their index file replaced.